SonicWall Warns of Escalating Cyberattacks Targeting Gen 7 Firewalls in Last 72 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has issued an urgent security advisory following a significant increase in cyber incidents targeting its Gen 7 SonicWall firewalls over the past 72 hours. The company is actively investigating a wave of attacks that appear to be focused on …

Hackers Can Steal IIS Machine Keys by Exploiting SharePoint Deserialization Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack method where hackers are exploiting a deserialization vulnerability in SharePoint to steal Internet Information Services (IIS) Machine Keys. This enables attackers to bypass security measures, forge trusted data, and ultimately achieve persistent Remote Code Execution (RCE) on …

Famous Chollima APT Hackers Attacking Job Seekers and Organization to Deploy JavaScript Based Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean-linked Famous Chollima APT group has emerged as a sophisticated threat actor, orchestrating targeted campaigns against job seekers and organizations through deceptive recruitment processes. Active since December 2022, this advanced persistent threat has developed an intricate multi-stage attack methodology …

Fashion Giant Chanel Hacked in Wave of Salesforce Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

French luxury fashion house Chanel has become the latest victim in a sophisticated cybercrime campaign targeting major corporations through their Salesforce customer relationship management systems. The company confirmed on July 25, 2025, that unauthorized threat actors had breached a database …

Critical Android System Component Vulnerability Allows Remote Code Execution Without User Interaction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google released its August 2025 Android Security Bulletin on August 4, revealing a critical vulnerability that poses significant risks to Android device users worldwide.  The most severe flaw, designated CVE-2025-48530, affects the core System component and could enable remote code …

New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Android malware campaign has emerged targeting Indian banking customers through convincing impersonations of popular financial applications. The malicious software masquerades as legitimate apps from major Indian financial institutions, including SBI Card, Axis Bank, Indusind Bank, ICICI, and …

NVIDIA Triton Vulnerability Chain Let Attackers Take Over AI Server Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability chain in NVIDIA’s Triton Inference Server that allows unauthenticated attackers to achieve complete remote code execution (RCE) and gain full control over AI servers.  The vulnerability chain, identified as CVE-2025-23319, CVE-2025-23320, and CVE-2025-23334, exploits the server’s Python …

WAFs protection Bypassed to Execute XSS Payloads Using JS Injection with Parameter Pollution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated method to bypass Web Application Firewall (WAF) protections using HTTP Parameter Pollution techniques combined with JavaScript injection.  The research, conducted by Bruno Mendes across 17 different WAF configurations from major vendors including AWS, Google Cloud, Azure, and Cloudflare, …

Raspberry Robin Malware Downloader Attacking Windows Systems With New Exploit for Common Log File System Driver Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape faces a persistent threat as Raspberry Robin, a sophisticated malware downloader also known as Roshtyak, continues its campaign against Windows systems with enhanced capabilities and evasion techniques. First identified in 2021, this USB-propagated malware has demonstrated remarkable …

Threat Actors are Actively Exploiting Vulnerabilities in Open-Source Ecosystem to Propagate Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The open-source software ecosystem, once considered a bastion of collaborative development, has become an increasingly attractive target for cybercriminals seeking to infiltrate supply chains and compromise downstream systems. Recent analysis conducted during the second quarter of 2025 reveals that threat …